This vulnerability allows remote attackers to execute arbitrary code on
vulnerable installations of Microsoft Internet Explorer.
The specific flaw exists within the Tabular Data Control ActiveX module.
Specifically, if provided a malicious DataURL parameter a stack
corruption may occur in the function CTDCCtl::SecurityCHeckDataURL. This
can be leveraged to execute arbitrary code under the context of the
current user.
WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation.
vulnerable installations of Microsoft Internet Explorer.
The specific flaw exists within the Tabular Data Control ActiveX module.
Specifically, if provided a malicious DataURL parameter a stack
corruption may occur in the function CTDCCtl::SecurityCHeckDataURL. This
can be leveraged to execute arbitrary code under the context of the
current user.
WARNING: This is an early release module. This is not the final version of this module. It is a pre-released version in order to deliver a module as quickly as possible to our customers that may be useful in some situations. Since this module is not the final version it may contain bugs or have limited functionality and may not have complete or accurate documentation.
CVE Link
Exploit Type - Old
Exploits/Client Side
Exploit Platform
Exploit Type
Product Name